RE: [PHP] securing an 'includes' dir

From: Date: Fri, 28 Jun 2002 17:27:01 +0000
Subject: RE: [PHP] securing an 'includes' dir
Groups: php.general 
Request: Send a blank email to php-general+get-104383@lists.php.net to get a copy of this message
The includes directory doesn't have to be inside the http root. For example, having the following directories: /www/www.somewhere.com/includes /www/www.somewhere.com/htdocs The htdocs is your http root. You could include a file in index.php like this: include("/www/www.somewhere.com/includes/functions.php"); You could also modify the Apache httpd.conf file and add the path to the include directory in the PHP path variable. -----Original Message----- > How might I make an 'includes' dir inside the http root and stop users > being able to browse it? chmod go-rwx dirname But this will probably stop the web server from reading the file. Perhaps the administrators can provide a script (SUID) that allows a user to change the group association of the file to that of the web server? Yet without making the user a part of the group itself, otherwise all users would be able to see all of these files... **************************************************************************** This message is intended for the sole use of the individual and entity to whom it is addressed, and may contain information that is privileged, confidential and exempt from disclosure under applicable law. If you are not the intended addressee, nor authorized to receive for the intended addressee, you are hereby notified that you may not use, copy, disclose or distribute to anyone the message or any information contained in the message. If you have received this message in error, please immediately advise the sender by reply email and delete the message. Thank you very much.

« previous php.general (#104383) next »